[TLS] Re: [Attested-tls] Re: Requesting feedback for expat BoF

2025-07-18 Thread Michael Richardson
requires. So yes, sometimes aCSR is not practical. They are not dependant nor mutually exclusive for the reasons you write in your email. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- *I*LIKE*TRAINS* signature.asc Description: PGP signature

[TLS] IoT certificate profile vs TLS SNI and subjectAltName

2025-01-06 Thread Michael Richardson
KI, Matter, OPC-UA, EAP-TEAP-BRSKI, ...) to replace any IDevID with otherName:EUI64 identity with a proper name that would fit into SNI. 4. Find a sensible way to extend RFC6066 to accomodote other forms of SNI. There isn't an IANA registry for this. -- Michael Richardson. o O ( IPv6

[TLS] Re: [Pqc] QUIC, amplification and PQC message sizes (was: Bytes server -> client)

2024-11-11 Thread Michael Richardson
gt; If would be very nice to have PQC variants that fit inside that budget. might it be worth doing a "legacy" crypto operation first, even if that is broken by a CRQC, if the time to break it is less than the RTT? -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =

Re: [TLS] I-D Action: draft-ietf-tls-subcerts-10.txt

2021-03-22 Thread Michael Richardson
On 2021-01-24 6:03 p.m., internet-dra...@ietf.org wrote: Filename: draft-ietf-tls-subcerts-10.txt I was looking at the DT, wondering what's up, wondering if there was any implementation report in the document. (When can I use this?... ) I see in the DT that it is waiting for W

Re: [TLS] [Emu] Fwd: Benjamin Kaduk's Discuss on draft-ietf-emu-eap-tls13-13: (with DISCUSS and COMMENT)

2021-01-05 Thread Michael Richardson
above: "to the EAP-TLS layer that the EAP-TLS method has finished" so I still think that there might be a typo :-) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature _

Re: [TLS] [Emu] Fwd: Benjamin Kaduk's Discuss on draft-ietf-emu-eap-tls13-13: (with DISCUSS and COMMENT)

2021-01-05 Thread Michael Richardson
Alan DeKok wrote: > Therefore, we need an explicit signal to the EAP-TLS layer that the Do you mean, "to the EAP layer"? s/EAP-TLS layer/EAP/ ?? > EAP-TLS method has finished. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works

Re: [TLS] [Last-Call] Iotdir last call review of draft-ietf-tls-md5-sha1-deprecate-04

2020-10-27 Thread Michael Richardson
Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ -- Michael Richardson. o O ( IPv6 IøT consulting )

Re: [TLS] [OPSAWG] CALL FOR ADOPTION: draft-reddy-opsawg-mud-tls

2020-09-19 Thread Michael Richardson
ber of cycles it is allowed to consume, otherwise the middle box might have to solve the halting problem :-) BPF could be another model. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls

Re: [TLS] [OPSAWG] CALL FOR ADOPTION: draft-reddy-opsawg-mud-tls

2020-09-18 Thread Michael Richardson
g one, but being an executable of a sort, it has other security problems. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ru

Re: [TLS] [OPSAWG] CALL FOR ADOPTION: draft-reddy-opsawg-mud-tls

2020-09-10 Thread Michael Richardson
On 2020-09-02 11:05 a.m., Joe Clarke (jclarke) wrote: Hello, opsawg. This draft as underwent a number of revisions based on reviews and presentations at the last few IETF meetings. The authors feel they have addressed the issues and concerns from the WG in their latest posted -05 revision.

Re: [TLS] [Network-tokens] Network Tokens I-D and TLS / ESNI

2020-08-01 Thread Michael Richardson
headers get, and the news is probably better than people feared, if I understood correctly. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ TLS mailing list TLS@ietf.org https://

Re: [TLS] something something certificate --- boiling a small lake

2020-06-26 Thread Michael Richardson
1.3. If that's not a concern, then it makes the whole problem. I guess I misunderstood the discussion. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sand

Re: [TLS] something something certificate --- boiling a small lake

2020-06-26 Thread Michael Richardson
Nico Williams wrote: > On Fri, Jun 19, 2020 at 12:50:17PM -0400, Michael Richardson wrote: >> Thus, a single header isn't enough, although there could be some degeneration >> that results in a single header. We need a few variables to update. >> &

Re: [TLS] something something certificate --- boiling a small lake

2020-06-25 Thread Michael Richardson
complexity would be in order to understand the ROI for this simiplicity. I think that a key line is figuring out how/if the certificate chain will be provided with the simplest design. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP s

[TLS] something something certificate --- boiling a small lake

2020-06-19 Thread Michael Richardson
e them wider. The hardware TLS offload box then is only important for adapting HTTP 1 and HTTP/2 connections to HTTP/3. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandel

Re: [TLS] [saag] Lessons learned from TLS 1.0 and TLS 1.1 deprecation

2019-10-01 Thread Michael Richardson
ter, to log and report the proportion of TLS version that connect. How can the IETF help? *An IETF standard for logging TLS connection parameters would help here* -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature

Re: [TLS] [saag] Lessons learned from TLS 1.0 and TLS 1.1 deprecation

2019-09-26 Thread Michael Richardson
spend more time addressing the issues that they have. We may not like their problems, we may even strongly disagree, but we have to keep them in the tent. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|I

Re: [TLS] publishing ESNIKeys under a .well-known URI...

2019-06-26 Thread Michael Richardson
be able to update the QNAMEs involved, because that usually permits the web server to delete A and records, as well as updating the ESNI ? Or did you mean "general write-access", meaning NFS or something like that? -- Michael Richardson , Sandelman Software Works -= IPv6 Io

[TLS] sending full certificate chains in ClientCertificate

2017-10-24 Thread Michael Richardson
itted...) which as far as I can see, is permited by tls1.3. Is there something I'm missing that would prevent us from doing this? -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature __